shopify-expert
Fail
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Detailed guidance in
references/performance-optimization.mdincludes a code example that dynamically loads and executes a script fromhttps://third-party.com/widget.js. This domain is flagged by security scanners as associated with botnet activity. - [METADATA_POISONING]: The
authorfield in theSKILL.mdfrontmatter identifies the developer ashttps://github.com/Jeffallan, which conflicts with the expected author context of1git2clone. - [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted configuration files and e-commerce data, creating a potential attack surface.
- Ingestion points: Shopify theme files (.liquid), app configuration (
shopify.app.toml), and GraphQL schemas processed via Shopify CLI. - Boundary markers: Absent. The skill lacks specific instructions to delimit or ignore instructions embedded in the Shopify data it processes.
- Capability inventory: The skill utilizes the Shopify CLI and Admin/Storefront APIs to perform file system writes and network operations.
- Sanitization: No explicit logic is provided to sanitize input from external templates or schemas before processing.
Recommendations
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata